Loading HuntDB...

Follow by email allows for following by unverified emails

Low
A
Automattic
Submitted None

Team Summary

Official summary from Automattic

The initial report outlined being able to add any email to a Tumblr account without verifying it first which is expected behavior that does not pose a security risk. However, the reporter also reported that these unverified emails were able to be used in our “follow by email” feature which we did consider to be a security risk. Our fix was to disallow follow by email for unverified emails.

Reported by myominthu_sec

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Violation of Secure Design Principles